<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>BenchProctor Blog</title><description>Engineering notes on SAST benchmarking — methodology, scoring, and coverage for measuring static analysis tools.</description><link>https://blog.benchproctor.com/</link><language>en-us</language><item><title>Java first: why we release one language at a time</title><link>https://blog.benchproctor.com/java-first-release-plan/</link><guid isPermaLink="true">https://blog.benchproctor.com/java-first-release-plan/</guid><description>BenchProctor&apos;s corpus spans nine languages, but we publish each only once it&apos;s verified production-ready. Java ships fully to the public before the end of June 2026 — here&apos;s why we&apos;re not dumping all nine at once.</description><pubDate>Sat, 30 May 2026 00:00:00 GMT</pubDate><category>release</category><category>roadmap</category><author>BenchProctor</author></item><item><title>How BenchProctor scores a SAST tool</title><link>https://blog.benchproctor.com/how-benchproctor-scores-sast-tools/</link><guid isPermaLink="true">https://blog.benchproctor.com/how-benchproctor-scores-sast-tools/</guid><description>The whole scoring model is a confusion matrix and one subtraction. Here&apos;s how true-positive and false-positive rates become a single number, why we average per category, and how the benchmark checks itself.</description><pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate><category>scoring</category><category>methodology</category><author>BenchProctor</author></item><item><title>Why static SAST benchmarks rot — and what quarterly rotation fixes</title><link>https://blog.benchproctor.com/why-static-sast-benchmarks-rot/</link><guid isPermaLink="true">https://blog.benchproctor.com/why-static-sast-benchmarks-rot/</guid><description>A frozen benchmark measures memorization as much as analysis. Here&apos;s the failure mode, and how rotating the corpus on a seed keeps scores honest without breaking comparability.</description><pubDate>Sun, 24 May 2026 00:00:00 GMT</pubDate><category>methodology</category><category>benchmarking</category><author>BenchProctor</author></item><item><title>Introducing BenchProctor: a SAST benchmark you can&apos;t game</title><link>https://blog.benchproctor.com/introducing-benchproctor/</link><guid isPermaLink="true">https://blog.benchproctor.com/introducing-benchproctor/</guid><description>A polyglot, anti-leakage, quarterly-rotated corpus for measuring how accurately a static analysis tool actually finds vulnerabilities — and how often it cries wolf.</description><pubDate>Wed, 20 May 2026 00:00:00 GMT</pubDate><category>announcement</category><category>methodology</category><author>BenchProctor</author></item></channel></rss>